CVE-2019-9659
9.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD
Description
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.
Affected (11)
Products: Chuango: Wifi Alarm System Firmware, Wifi/cellular Smart Home System H4 Plus Firmware, Awv Plus Wifi Alarm System Firmware, G5 Plus Gsm/sms/rfid Touch Alarm System Firmware, G3 Gsm/sms Alarm System Firmware, G5w 3g Firmware, B11 Dual Network Alarm System Firmware, A8 Pstn Alarm System Firmware, A11 Pstn/lcd/rfid Touch Alarm System Firmware, Cg 105s On Site Alarm System Firmware · Eminent: Em8617 Ov2 Wifi Alarm System Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Chuango Wifi Alarm System | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Chuango Wifi/cellular Smart Home System H4 Plus | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Chuango Awv Plus Wifi Alarm System | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Chuango G5 Plus Gsm/sms/rfid Touch Alarm System | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Chuango G3 Gsm/sms Alarm System | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Chuango G5w 3g | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Chuango B11 Dual Network Alarm System | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Chuango A8 Pstn Alarm System | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Chuango A11 Pstn/lcd/rfid Touch Alarm System | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Chuango Cg 105s On Site Alarm System | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Eminent Em8617 Ov2 Wifi Alarm System | All versions |
References (2)
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.